EP1186183A1 - Sat back channel security solution for mobile terminals using ussd - Google Patents
Sat back channel security solution for mobile terminals using ussdInfo
- Publication number
- EP1186183A1 EP1186183A1 EP00946576A EP00946576A EP1186183A1 EP 1186183 A1 EP1186183 A1 EP 1186183A1 EP 00946576 A EP00946576 A EP 00946576A EP 00946576 A EP00946576 A EP 00946576A EP 1186183 A1 EP1186183 A1 EP 1186183A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- proxy
- data
- ussd
- server
- mobile terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0281—Proxies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
- H04W12/033—Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0442—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/12—Messaging; Mailboxes; Announcements
- H04W4/14—Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]
Definitions
- the present invention relates to mobile communication, in particular security solutions for mobile terminals using USSD (Unstructured Supplementary Service Data) .
- USSD Unstructured Supplementary Service Data
- the WML server sends the content of a WML page to the Proxy
- the ME sends the received data to the display, which presents said data to the user
- the ME sends the input to the proxy 6.
- the proxy assembles the received input into WML format and delivers it to the WML server
- the only security feature that exists is the unencrypted passwords.
- This security feature is implemented in the SAT applications, which implement the information browsing.
- Figure 1 illustrates the simulation of a WAP information dialogue using USSD (prior art) .
- Figure 2 illustrates a secure WAP exchange according to the invention using an SAT back channel.
- a secret/private key is stored on the SIM card. Also an algorithm for signing data using a symmetric or an asymmetric technique, as well as an application handling the dialogue with the user and the signing of data is stored on the SIM card.
- the USSD dialogue is terminated. Instead the proxy enters the details of the transaction to be secured into an SMS, and sends it to the SIM card of the Mobile Terminal where the SAT application is activated.
- the application using SAT commands shows the details of the transaction to the user, and prompts for an "OK" to the transaction. 4. If the user agrees (optionally by entering a PIN), the application signs the data (or a hash of the data) with the secret/private key using the correct algorithms.
- the signed data is then returned to the proxy by using SMS or USSD as a bearer.
- the proxy either verifies the signature or passes it on to the appropriate instance that shall handle the verification.
- the application on the SIM card can be made very thin and flexible. Thus, it can be made to work in many different applications.
- the system handling the information browsing, and the system handling the security of the transactions are separated. They can be updated, changed etc. independently.
- Application An application consists of a set of security mechanisms, files, data and protocols (excluding transmission protocols)
- HTML The document format used on the World Wide Web. Web pages are built with HTML tags or codes embedded in the text. HTML defines the page layout, fonts and graphic elements, as well as the hypertext links to other documents on the Web.
- Proxy It is also called a “proxy server” or “application level gateway” . It is an application that breaks the connection between the sender and the receiver. All input is forwarded to a different port, closing a straight path between two networks and preventing a hacker from obtaining internal addresses and details of a private network.
- SAT is a set of applications and related procedures, which may be used during a GSM session .
- USSD Unstructured Supplementary Service Data USSD is a mechanism that allows user interaction between GSM Public Land Mobile Network applications and a Mobile Station in a transparent way through the network.
- WAP is a wireless standard from Motorola, Ericsson and Nokia for providing mostly cellular phones with access to e-mail and text-based Web pages.
- WAP uses the Wireless Markup Language (WML) , which is the WAP version of HDML.
- WML Wireless Markup Language
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Business, Economics & Management (AREA)
- Signal Processing (AREA)
- Accounting & Taxation (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Finance (AREA)
- Strategic Management (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| NO19992839A NO311000B1 (en) | 1999-06-10 | 1999-06-10 | Security solution for mobile phones with WAP |
| NO992839 | 1999-06-10 | ||
| PCT/SE2000/001169 WO2000078070A1 (en) | 1999-06-10 | 2000-06-06 | Sat back channel security solution for mobile terminals using ussd |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1186183A1 true EP1186183A1 (en) | 2002-03-13 |
Family
ID=19903445
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP00946576A Withdrawn EP1186183A1 (en) | 1999-06-10 | 2000-06-06 | Sat back channel security solution for mobile terminals using ussd |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US6795924B1 (en) |
| EP (1) | EP1186183A1 (en) |
| JP (1) | JP2003502759A (en) |
| AU (1) | AU6031200A (en) |
| NO (1) | NO311000B1 (en) |
| WO (1) | WO2000078070A1 (en) |
Families Citing this family (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| SE522260C2 (en) * | 1999-10-01 | 2004-01-27 | Ericsson Telefon Ab L M | Method, system and security adapter for executing secure data transmission in a wireless network |
| FR2800228B1 (en) * | 1999-10-26 | 2002-02-08 | Wavecom Sa | SYSTEM AND METHOD FOR CONTROLLING THIRD PARTY EQUIPMENT THROUGH A SIM CARD THROUGH A RADIO COMMUNICATION MODULE, CORRESPONDING RADIO COMMUNICATION MODULE AND THIRD PARTY EQUIPMENT |
| US20020087596A1 (en) * | 2000-12-29 | 2002-07-04 | Steve Lewontin | Compact tree representation of markup languages |
| TWI224455B (en) * | 2001-01-19 | 2004-11-21 | Mitake Data Co Ltd | End-to-end encryption procedure and module of M-commerce WAP data transport layer |
| FR2821222B1 (en) * | 2001-02-16 | 2003-04-18 | Bull Cp8 | ANONYMOUS COMMUNICATION ESTABLISHMENT METHOD |
| NO314649B1 (en) * | 2001-04-25 | 2003-04-22 | Ericsson Telefon Ab L M | Procedures for non-repudiation using cryptographic signatures are small entities |
| NO313810B1 (en) * | 2001-04-25 | 2002-12-02 | Ericsson Telefon Ab L M | Cryptographic signing in small units |
| US6944760B2 (en) * | 2001-05-24 | 2005-09-13 | Openwave Systems Inc. | Method and apparatus for protecting identities of mobile devices on a wireless network |
| EP1261170A1 (en) * | 2001-05-24 | 2002-11-27 | BRITISH TELECOMMUNICATIONS public limited company | Method for providing network access to a mobile terminal and corresponding network |
| US7216237B2 (en) * | 2001-07-16 | 2007-05-08 | Certicom Corp. | System and method for trusted communication |
| WO2003084175A1 (en) * | 2002-03-27 | 2003-10-09 | Barracuda Innovations Pte Ltd. | A system and method for secure electronic transaction using a registered intelligent telecommunication device |
| DE10227091A1 (en) * | 2002-06-18 | 2004-01-15 | E-Plus Mobilfunk Gmbh & Co. Kg | Method for making information available in telecommunications networks and microprocessor card with corresponding applications for communication with the relevant telecommunications network |
| GB0329502D0 (en) * | 2003-12-19 | 2004-01-28 | Nokia Corp | Control decisions in a communication system |
| US8050653B2 (en) | 2004-03-22 | 2011-11-01 | Research In Motion Limited | System and method for viewing message attachments |
| JP4950282B2 (en) * | 2006-04-28 | 2012-06-13 | ジェムアルト エスアー | Data transmission between server and communication object |
| US8040921B2 (en) * | 2007-06-15 | 2011-10-18 | Sony Ericsson Mobile Communications Ab | Method and apparatus for controlling the transfer of private information in a communication system |
| US7949355B2 (en) * | 2007-09-04 | 2011-05-24 | Research In Motion Limited | System and method for processing attachments to messages sent to a mobile device |
| US8254582B2 (en) | 2007-09-24 | 2012-08-28 | Research In Motion Limited | System and method for controlling message attachment handling functions on a mobile device |
| US8099764B2 (en) | 2007-12-17 | 2012-01-17 | Microsoft Corporation | Secure push and status communication between client and server |
| US20090220084A1 (en) * | 2008-02-29 | 2009-09-03 | Research In Motion Limited | System and method for dynamically updating message list indicators |
| US9071616B2 (en) | 2010-11-18 | 2015-06-30 | Microsoft Technology Licensing, Llc | Securing partner-enabled web service |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5537474A (en) * | 1994-07-29 | 1996-07-16 | Motorola, Inc. | Method and apparatus for authentication in a communication system |
| CN1230324A (en) * | 1996-07-11 | 1999-09-29 | 格姆普拉斯有限公司 | Enhanced short messages and method of synchronizing and securing enhanced short message exchange in a cellular telecommunication system |
| GB2327567A (en) * | 1997-07-17 | 1999-01-27 | Orange Personal Comm Serv Ltd | Controlling Access to SMSCB Service |
| FR2771205B1 (en) * | 1997-11-20 | 2000-01-21 | Gemplus Card Int | METHOD, CHIP CARD AND TERMINALS FOR PERFORMING TRANSACTIONS THROUGH A TELECOMMUNICATION NETWORK |
| FI980085A0 (en) * | 1998-01-16 | 1998-01-16 | Finland Telecom Oy | Encryption in card form and annulling in encryption |
| US6317831B1 (en) * | 1998-09-21 | 2001-11-13 | Openwave Systems Inc. | Method and apparatus for establishing a secure connection over a one-way data path |
| GB2342817A (en) * | 1998-10-16 | 2000-04-19 | Nokia Mobile Phones Ltd | Secure session setup based on wireless application protocol |
-
1999
- 1999-06-10 NO NO19992839A patent/NO311000B1/en unknown
-
2000
- 2000-06-06 WO PCT/SE2000/001169 patent/WO2000078070A1/en not_active Ceased
- 2000-06-06 JP JP2001504195A patent/JP2003502759A/en active Pending
- 2000-06-06 EP EP00946576A patent/EP1186183A1/en not_active Withdrawn
- 2000-06-06 AU AU60312/00A patent/AU6031200A/en not_active Abandoned
- 2000-06-09 US US09/589,810 patent/US6795924B1/en not_active Expired - Lifetime
Non-Patent Citations (1)
| Title |
|---|
| See references of WO0078070A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| AU6031200A (en) | 2001-01-02 |
| NO992839D0 (en) | 1999-06-10 |
| US6795924B1 (en) | 2004-09-21 |
| NO311000B1 (en) | 2001-09-24 |
| JP2003502759A (en) | 2003-01-21 |
| WO2000078070A1 (en) | 2000-12-21 |
| NO992839L (en) | 2000-12-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US6795924B1 (en) | Sat back channel security solution | |
| EP1216538B1 (en) | Method and apparatus for executing secure data transfer in a wireless network | |
| US6647260B2 (en) | Method and system facilitating web based provisioning of two-way mobile communications devices | |
| KR100458917B1 (en) | Accessing a server computer | |
| US8171291B2 (en) | Method for checking the integrity of data, system and mobile terminal | |
| US6925568B1 (en) | Method and system for the processing of messages in a telecommunication system | |
| EP2106191B1 (en) | A method for updating a smartcard and a smartcard having update capability | |
| KR20010041363A (en) | Method, arrangement and apparatus for authentication through a communications network | |
| JP2010259074A (en) | Setting up sensitive sessions based on wireless application protocols | |
| EP1680940B1 (en) | Method of user authentication | |
| US7698747B2 (en) | Applet download in a communication system | |
| US7945246B2 (en) | System and method for establishing authenticated network communications in electronic equipment | |
| CN111246455B (en) | Registration activation method, equipment and computer readable storage medium | |
| US20060092953A1 (en) | Proxy smart card applications | |
| EP1236367A1 (en) | Safe information interchange between a user of a terminal and a sim application toolkit via wap | |
| EP1844417B1 (en) | Method and system for restricted service access | |
| EP2378800B1 (en) | Secure communication system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20011026 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE |
|
| AX | Request for extension of the european patent |
Free format text: AL;LT;LV;MK;RO;SI |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL) |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20061201 |